CVE-2026-105744: CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine
CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine Vulnerability ID: CVE-2026-105744 CVSS Score: 7.5 Published: 2026-10-07 Docling, a tool for parsing and processing diverse do
CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine
Vulnerability ID: CVE-2026-105744
CVSS Score: 7.5
Published: 2026-10-07
Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.
TL;DR
A high-severity vulnerability in Docling's optional Tectonic rendering engine allows remote attackers to read arbitrary files, overwrite critical server assets, or execute arbitrary commands via crafted LaTeX inputs containing malicious TikZ macros.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22, CWE-73, CWE-1188
- Attack Vector: Network
- CVSS Score: 7.5 (High)
- EPSS Score: 0.00304 (Percentile: 21.27%)
- Exploit Status: Proof of Concept (PoC) available
- CISA KEV Status: Not Listed
Affected Systems
- Docling Document Parsing Applications running Tectonic rendering
- Docling Slim installations with Tectonic engine enabled
-
docling: >= 2.94.0, < 2.132.0 (Fixed in:
2.132.0) -
docling-slim: >= 2.94.0, < 2.132.0 (Fixed in:
2.132.0)
Code Analysis
Commit: 38b6fa0
Fix TikZ compile path traversal and sandbox Tectonic execution by introducing --untrusted and --only-cached flags and implementing a static LaTeX source validation regex filter
Mitigation Strategies
- Upgrade the Docling installation to version 2.132.0 or newer.
- Avoid enabling Tectonic rendering unless required.
- Isolate document processing within restricted sandbox environments (Docker with read-only filesystems or gVisor).
Remediation Steps:
- Run 'pip install --upgrade docling docling-slim' to update package dependencies.
- Verify that configurations utilizing LatexBackendOptions explicitly avoid setting 'tikz_engine' to 'tectonic' or 'tikz_engine_allow_shell_escape' to True unless securely sandboxed.
References
Read the full report for CVE-2026-105744 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.